Module 2 · ISO 27001:2022 Implementation

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 22, 2026
4 min read
Read as

Last updated: April 29, 2026

Required documents, the SoA, 2022 control structure, implementation timeline, common gaps for Indian implementations.

ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). For Indian organisations selling globally, it is often the first formal certification pursued — recognized in nearly every market, scoped flexibly, and well-understood. This module covers what ISO 27001:2022 actually requires, the implementation timeline, and the operational realities of getting and keeping certified.

What ISO 27001 actually is

  • An ISMS standard — an system for managing security, not a checklist of controls
  • Process-oriented: requires risk assessment, treatment plans, continuous improvement
  • Annex A includes 93 reference controls (down from 114 in the 2013 version) you may select from
  • Certifiable by accredited bodies (BSI, DNV, TUV, BSI India, etc.)
  • 3-year cycle: initial certification audit, surveillance audits years 2 and 3, recertification at year 4

The required documents

ISO 27001 requires specific documented information:

  • ISMS scope statement — which parts of the org are in scope
  • Information security policy
  • Risk assessment methodology
  • Risk assessment report
  • Risk treatment plan
  • Statement of Applicability (SoA) — for each Annex A control: applicable yes/no, justification, implementation status
  • Internal audit programme
  • Management review records
  • Corrective action records
  • Various procedure documentsincident response, access management, change management, etc.

The 2022 control structure

Annex A controls in 27001:2022 are organized into 4 themes (down from 14 in 2013):

  • Organisational (37 controls) — policies, roles, supplier relationships, threat intelligence
  • People (8 controls) — screening, training, NDA, disciplinary process
  • Physical (14 controls) — perimeters, equipment, secure disposal
  • Technological (34 controls) — access management, crypto, logging, web filtering, secure coding

11 new controls added in 2022 reflect cloud + supply chain reality: Threat Intelligence (5.7), Information Security for Cloud Services (5.23), ICT Readiness for Business Continuity (5.30), Configuration Management (8.9), Web Filtering (8.23), Secure Coding (8.28), and others.

The Statement of Applicability — the heart of the certification

For every Annex A control, the SoA documents:

  • Whether it applies (yes/no)
  • Justification for the decision
  • Implementation reference (which procedure / system delivers it)
  • Implementation status (planned, partially implemented, fully implemented)

Auditors use the SoA as their map. A weak SoA — vague justifications, untraceable implementations — fails certification. A clean SoA accelerates audit dramatically.

Implementation timeline (realistic)

For a 50-200 employee Indian company with no prior ISMS:

  • Months 1-2: scope, policy, governance setup. Form the steering committee
  • Months 3-4: risk assessment methodology + initial assessment
  • Months 5-7: control gap analysis; implement missing controls
  • Months 8-9: internal audit and management review
  • Months 10-11: Stage 1 audit (documentation review)
  • Months 11-12: Stage 2 audit (operational verification)
  • Month 12-13: certificate issued (pending CB internal review)

Compressing below 8 months requires doubling the team or accepting deferred remediations. Above 18 months suggests sustained scope/will issues.

Common gaps for Indian implementations

  • Risk assessment depth. Auditors want detailed risk identification + treatment, not generic “data may be lost”
  • Internal audit coverage. Must cover all Annex A controls applicable; many programs only audit a subset
  • Management review evidence. Quarterly meetings with documented inputs and outputs; agenda items prescribed by the standard
  • Supplier security. Annex A control 5.19-5.23 requires structured third-party assessment; often done informally
  • Incident response evidence. Auditors want to see real incidents handled per procedure, not just the procedure itself
  • Asset inventory completeness. Information assets, not just IT — including people, processes, locations

Choosing a certification body

Not all certification bodies (CBs) are equal. Considerations:

  • Accreditation: ensure CB is accredited by an IAF-recognized body (NABCB in India)
  • Sector experience: SaaS, banking, manufacturing — pick a CB that’s audited your sector
  • Auditor language: ensure auditors can communicate in English (or local language) with your team
  • Timing: some CBs have 3-month booking lead times
  • Cost: ₹3-8 lakh for a typical small/mid SaaS initial certification + Stage 1+2; surveillance audits ~60% of initial cost annually

What auditors actually check

Stage 1 (documentation):

  • Scope statement is clear
  • Policies exist, signed by top management
  • SoA is complete and traceable
  • Risk methodology is documented and applied
  • Procedures referenced in SoA exist

Stage 2 (operational):

  • Sample of records — recent risk assessment, recent management review, recent incidents
  • Interview control owners — do they know their control?
  • Trace evidence for selected controls — pick a couple of access reviews, change tickets, etc., and verify execution
  • Walk through 2-3 procedures from start to finish
  • Inspect physical security if in-scope

Surveillance audits — keeping the certificate

Annual surveillance audits (lighter than the initial) catch drift. Common surveillance findings:

  • Internal audit not completed on schedule
  • Risk treatment plan not updated after a known incident
  • Management review not held
  • New systems brought into scope without ISMS update
  • Asset inventory not updated for departures/new hires

“Major nonconformity” in a surveillance audit can trigger certificate suspension. Treat surveillance like a real audit.

27001 vs SOC 2 — choosing

  • Selling primarily to US enterprises: SOC 2 first, often required by procurement
  • Selling primarily to EU / global / non-US: ISO 27001 first
  • Selling to both: pursue ISO 27001 first (broader coverage), then add SOC 2 mapping (significant overlap means much less marginal work)

Maintaining the ISMS year-round

  • Risk assessment refresh — at least annually; whenever scope changes significantly
  • Policy review — annual review even if no changes
  • Internal audit — typically twice a year; cover all controls over the cycle
  • Management review — quarterly with prescribed agenda
  • Incident metrics — count, severity, MTTR; presented at management review
  • Vendor risk assessments — for new vendors and annual for existing

What the next modules cover

Module 3 covers SOC 2 — the framework most relevant if your customer base is US enterprises. Module 4 covers third-party / vendor risk management as a discipline. Module 5 covers running internal audits effectively.

🧠
Check your understanding

Module Quiz · 15 questions

Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.

Want this for your team?

Custom team training + practitioner advisory

Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.

Book team training call Replies in 4 working hrs · India-only · Senior consultants